Referral Program Flaw Costs Level Finance $1.1M in BSC Exploit
BSC-based perpetuals platform Level Finance had $1.1 million siphoned out of its referral rewards system the day before this report.
Researcher definalist flagged the attack on social media while it was still in progress, and the Level Finance team confirmed the incident roughly two hours afterward.

Fortunately, the damage stayed confined to the referral program itself — the project's treasury and liquidity pool were untouched. As the attacker converted stolen LVL tokens into BNB, the sell pressure briefly knocked LVL's price down 65%, though it has since largely recovered.
Notably, this wasn't the attacker's first attempt: an earlier try at the same exploit had been made more than a week prior, but it went unnoticed at the time.
Analysis from Peckshield and BlockSec traced the root cause to Level Finance's LevelReferralControllerV2 contract, which had a flaw allowing the same referral reward claim to be processed multiple times within a single epoch.
To set up the exploit, the attacker first generated a large number of referral accounts, then used flash loans to execute swaps that pushed those referrals into higher reward tiers. The underlying bug was that the contract's claimMultiple function never verified whether a given epoch had already been claimed against.
Key on-chain identifiers from the incident:
- Exploiter's wallet: 0x70319d1c09e1373fc7b10403c852909e5b20a9d5
- Example transaction: 0xe1f257041872c075cbe6a1212827bc346df3def6d01a07914e4006ec43027165
- LevelReferralControllerV2 contract: 0x977087422C008233615b572fBC3F209Ed300063a
Both Quantstamp and Obelisk had previously reviewed LevelReferralControllerV2 as part of their audits of the project's Core contracts, and neither flagged this issue.
Update, May 9, 2023: Quantstamp reached out afterward to clarify that the vulnerable code postdated their audit. Their statement, provided via direct message, read in part:
The vulnerability was included in an upgrade done on April 18 (bscscan.com/tx/0xe0a8e635f…) that upgraded the proxy of LevelReferralControllerV2 (bscscan.com/address/0x9770…) to the vulnerable implementation (bscscan.com/address/0x9f00…).
This code is different to the commit audited by Quantstamp as stated in the audit report (certificate.quantstamp.com/full/level-fin…). The source code for the vulnerable implementation in question is not committed in the official public repository of Level Finance in GitHub (github.com/level-fi/level…).

By the end of the attack, the exploiter had extracted 214,000 LVL tokens, which were swapped for 3,345 BNB — worth about $1.1 million at the time. Those funds have remained sitting in the attacker's wallet. The resulting sell-off dragged LVL's market price down from $8.42 to a low of $2.93, a 65% decline, before it recovered much of that ground in the aftermath.
BlockSec pointed out that the roughly week-long gap between the attacker's initial, failed attempt and the eventual successful exploit illustrates the value on-chain monitoring tools could have offered here. Systems such as Forta, Sentinel, and Spotter are built to flag newly deployed contracts written to interact with DeFi protocols in atypical ways, giving teams an early warning.
Such a long lead time before an attack is unusual, however — most exploits offer far less notice. A DeFi protocol can go from secure to compromised within a single block, and typically an attack contract only needs to be deployed shortly before the hack itself is triggered. Even so, a warning window of just a few minutes can matter for more centralized protocols capable of pausing their contracts on short notice. Where that isn't an option, BlockSec's own whitehat frontrunning system has stepped in on multiple past occasions to intercept attackers and preserve funds.
Widespread, automated on-chain defenses for fully decentralized, self-executing systems still look some distance off — but incidents like this one suggest the direction the industry may eventually need to head.
Get new scam files the moment we publish them — usually 2–3 emails a week.